Security Engineer III, Red Team Operator (TS Clearance)
Cloud Platforms
Cybersecurity Tools
Data Security
Endpoint Security
Engineer
Ethical Hacking
Incident Response
Information Security
InfoSec
Offensive Security
Project Management
Red Team
Red Team Operator
Risk Management
Security
Security Automation
Security Clearance
Security Engineering
Security Operations
Security Testing
Security Testing Tools
Job Description
Join Deloitte’s Cyber Defense & Resilience team as a Security Engineer III, Red Team Operator, delivering adversary emulation to strengthen detection, response, and resilience across enterprise environments.
Responsibilities
- Plan and execute red team operations across enterprise environments, web applications, cloud platforms, and endpoints
- Emulate advanced threat actors using realistic attack paths, tools, and techniques
- Run simulations for reconnaissance, initial access, privilege escalation, lateral movement, persistence, and exfiltration
- Evaluate the effectiveness of security controls, monitoring, and incident response processes
- Conduct authorized phishing, social engineering, and credential attack exercises
- Develop custom payloads, scripts, and attack workflows to support engagements
- Document findings, attack chains, defensive gaps, and remediation recommendations
- Deliver after-action reports and debriefs to technical and leadership stakeholders
- Collaborate with blue teams, detection engineers, and security leadership to improve defensive capabilities
- Maintain strict adherence to rules of engagement, legal requirements, and operational safety
Requirements
- Bachelor’s degree in Cybersecurity, Computer Science, Information Systems, Engineering, or a related technical field
- Active Top-Secret Clearance
- Onsite availability up to 5 days per week in Baltimore, MD
- 2+ years of experience with:
- Network architecture, protocols, and techniques (example: tunneling)
- Hands-on offensive security in red teaming, purple teaming, or adversary simulation
- Enterprise attack techniques across Windows, Active Directory, Linux, cloud, and identity environments
- Command and control frameworks, privilege escalation, lateral movement, and evasion techniques
- Tooling proficiency including Cobalt Strike, Mythic, Metasploit, BloodHound, Burp Suite, Nmap, and PowerShell or Python
- MITRE ATT&CK mapping and threat emulation
- Ability to write high-quality reports connecting technical results to business risk
- CRTO (Certified Red Team Operator) or OSCP (Offensive Security Certified Professional)
- Ability to travel 20%, on average, based on work and client/industry needs
- Legally authorized to work in the United States without employer sponsorship, now or in the future
Technologies
- Cobalt Strike
- Mythic
- Metasploit
- BloodHound
- Burp Suite
- Nmap
- PowerShell
- Python
- MITRE ATT&CK
- Havoc
- Sliver
- AWS
- Azure
- GCP
Team
- Deloitte Cyber helps address the unique challenges and opportunities businesses face in cybersecurity
- Cyber Defense & Resilience supports clients in defending against advanced threats by transforming security operations, monitoring technology, data analytics, and threat intelligence
- Supports management and protection of dynamic attack surfaces and rapid crisis and cyber incident response to enable readiness, response, and recovery from business disruptions
Skills for Success
- Ability to work independently and collaborate with a team
- Effective written and verbal communication skills
- Meticulous attention to detail and quality of work product
- Ability to build and sustain professional relationships
- Ability to lead projects or workstreams
- Ability to manage and prioritize multiple tasks in a fast-paced environment
- Strong interpersonal skills and professional demeanor
- Ability to meet deadlines
- Ability to provide clear guidance to others
Preferred
- Experience with C2 frameworks such as Cobalt Strike, Havoc, Mythic, Sliver
- Experience with cloud red teaming in AWS, Azure, or GCP
- Familiarity with detection engineering, SIEM, EDR, and purple team exercises
- Experience developing custom tooling or modifying public offensive tools
- Knowledge of malware analysis, reverse engineering, or exploit development
Salary range: USD 119,000 - 218,300 per year